Background

The EU General Data Protection Regulation (“EU GDPR”) and the UK General Data Protection Regulation (“UK GDPR” and collectively with the EU GDPR, the “GDPR”) places restrictions on personal data transfers to certain countries outside of the European Economic Area (“EEA”) and the UK.

An “adequacy decision” from the European Commission and comparable certification by the UK government are key mechanisms companies rely upon to comply with these GDPR restrictions. Specifically, “positive” “adequacy decisions” made by the European Commission can deem that either all data transfers to the relevant country, or transfers made under certain pre-approved data transfer mechanisms to the relevant country, are deemed to satisfy such GDPR restrictions. To illustrate, the European Commission’s “positive” “adequacy decision” for the EU-U.S. Privacy Shield allowed EEA-based companies to transfer – in compliance with the GDPR – personal data to U.S. based companies that had certified to the Privacy Shield program. However, the Privacy Shield “adequacy decision” was invalidated by the EU’s highest court – the Court of Justice of the European Union (the “CJEU”) – in 2020 in the Schrems II decision. In turn, since the Schrems II decision, companies that had relied on the Privacy Shield have had to use alternate data transfer mechanisms to comply with the EU GDPR.

The UK still has its own version of the EU GDPR – namely, the UK GDPR in place following its exit from the EU; and case law, such as the Schrems II decision issued before “Brexit” continue apply to the UK. Therefore, and despite Brexit, similar issues have continued to be experienced with respect to data flows from the UK to the U.S. to those outlined above.

The Scope of the Executive Order

In light of the Schrems II decision, the Executive Order seeks to accomplish two key objectives to allow for the creation of the Framework:

  • impose restrictions on access by the U.S. government to data transferred from certain overseas jurisdictions (including from the EEA and the UK). Specifically, the Executive Order provides binding safeguards that limit access to data by U.S. intelligence authorities to what is necessary and proportionate to protect national security. Alleged extensive U.S. government access to EEA-originating personal data transferred under the Privacy Shield mechanism was a chief concern of the CJEU in Schrems II; and

Next Steps for the Framework

The Framework is not likely to be available for use by companies before the end of this year. This is because separate “adequacy decisions” will first need to be issued – following potentially protracted and uncertain governmental and legislative processes – by the European Commission and the UK government by reference to the new data protections afforded by the Executive Order; however, both the Commission and the UK government have welcomed the Executive Order. In FAQ’s released in response to the Executive Order, the European Commission called the measures in the Executive Order “significant improvements”. The UK Government has also welcomed the publication of the Executive Order saying that it “strengthens the safeguards and establishes new redress routes for UK data processed by US authorities”.

Once “adequacy decisions” are issued by the European Commission and UK government, US companies can seek to be certified by the U.S. Department of Commerce under the Framework. US companies will be able to certify to the Framework by committing to comply with a detailed set of privacy obligations. While those obligations are not yet detailed, we expect that certain core GDPR principles will be among them, such as data minimization, purpose limitation, and certain data subject rights.

Photo of Kelly McMullon Kelly McMullon

Kelly M. McMullon is special international labor, employment & data protection counsel in the Labor & Employment Law Department and member of the Firm’s International Labor & Employment, Privacy & Cybersecurity and Sports Groups. Kelly has been recommended in Legal 500 UK for…

Kelly M. McMullon is special international labor, employment & data protection counsel in the Labor & Employment Law Department and member of the Firm’s International Labor & Employment, Privacy & Cybersecurity and Sports Groups. Kelly has been recommended in Legal 500 UK for her “responsiveness and practicality.”

Kelly assists clients in a variety of sectors including financial services, asset management, life sciences, fintech, consultancy, retail, sports, leisure and manufacturing in a wide range of contentious and non-contentious matters.

In her employment practice, she provides general day-to-day counselling and advice on all employment-related issues, including hires, terminations, grievances and redundancies, as well as the employment aspects of transactions.

In her data protection practice, Kelly provides strategic advice as well as practical support and guidance on all aspects of data protection compliance, including international transfers of personal data, data breaches, direct marketing and employee data protection concerns. She also provides advice on the data protection aspects of transactions.

Kelly also has experience working with businesses on CSR and ESG initiatives, human rights and modern slavery issues.

Kelly is a contributor to Proskauer’s International Labor and Employment Law and Proskauer on Privacy blogs and is the Editor for Proskauer on Privacy’s “International Data Privacy” chapter. She regularly provides training and speaks on employment and data protection issues.

Her pro bono experience includes counselling not-for-profit organizations on data privacy and employment-related issues.